Wire · regulatory
Critical GitLab vulnerability exploited days after disclosure
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 August 2026 · Fusion42 review
A critical vulnerability (CVE-2026-19478) in self-managed GitLab Community and Enterprise Editions is being actively exploited shortly after disclosure, allowing unauthenticated attackers to modify or delete public repositories and user data.
This Wire brief sits within Fusion42's coverage of Enterprise Software, Developer Tools and Cybersecurity, and 4 sources have reported it between 17 Aug 2026 and 21 Aug 2026.
◆ ◆ The Wire takeaway
You must act fast to patch your GitLab instances or limit public repository access immediately because attackers are exploiting this flaw without credentials. Internal GitLab deployments are still at risk if network access is not tightly controlled.
◆ Coverage
4 sources · first reported 17 Aug 2026 · latest 21 Aug 2026
◆ Related on Wire
◆ Topics